Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-94613— authentik: Denial of Service via Document Type Declarations in SAML Messages

Quick assessment

Affected
goauthentik authentik
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

authentik 是一款开源的身份提供商(Identity Provider)。在版本 2026.2.7、2026.5.7 和 2026.8.2 之前,未认证的攻击者可以向部署了 authentik 且配置为身份提供商(identity-provider)角色或 SAML 源(SAML source)角色的系统中提交格式错误的 SAML 消息。此类消息可能导致处理 或 路径的 worker 进程停止响应,从而使分配给该 worker 的请求失败。 尽管 worker 进程的终止和自动重启不会导致基于数据库的会话丢

CVSS 7.5 · High EPSS 0.64% · P49

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 3

VendorProduct Version RangeStatus
goauthentik authentik < 2026.2.7 affected
>= 2026.5.0, < 2026.5.7 affected
>= 2026.8.0, < 2026.8.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-94613

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
authentik: Denial of Service via Document Type Declarations in SAML Messages
Source: CVE Program / CVE List V5
Vulnerability Description
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an unauthenticated attacker can submit a malformed SAML message to an authentik deployment using SAML in either the identity-provider or SAML source role. The message can stop the worker handling /application/saml/* or /source/saml/*, causing the requests assigned to that worker to fail. Worker process termination and automatic restart do not destroy database-backed sessions, but continued malicious messages can cause a sustained share of legitimate traffic to fail. Other protocol implementations are not affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
不加限制或调节的资源分配
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
goauthentik authentik < 2026.2.7 -

II. Public POCs for CVE-2026-94613

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-94613

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-94613 (8)

Vendor Advisories for CVE-2026-94613 (2)

Vendor Pages for CVE-2026-94613 (4)

Same Patch Batch · goauthentik · 2026-09-24 · 5 CVEs total

CVE-2026-94606 8.9 HIGH authentik: MFA Bypass via State Confusion / Parameter Injection in AuthenticatorEmailStage
CVE-2026-94609 8.8 HIGH authentik: Privilege Escalation to Superuser via Group Hierarchy
CVE-2026-94611 8.1 HIGH authentik: Stored credentials are readable with view permission alone
CVE-2026-94612 7.4 HIGH authentik: Authentication bypass via assertion confusion in SAML sources

IV. Related Vulnerabilities

V. Comments for CVE-2026-94613

No comments yet


Leave a comment